logo

Advent of Configuration Extraction – Part 3: Mapping GOT/PLT and Disassembling the SNOWLIGHT Loader

ID: d08d3692-53b5-5a55-a4c6-5091e9168fae

STIX ID: report--d08d3692-53b5-5a55-a4c6-5091e9168fae

Feed Name: Sekoia.io Blog

Threat Score
72/100

Date Published: 2025-12-15

Date Updated: 2026-04-29

Author: Jeremy Scion, Pierre Le Bourhis and Sekoia TDR

...
...

**SNOWLIGHT** is a compact ELF downloader used to fetch and execute remote payloads in memory; this analysis documents how to extract its C2 address and port by parsing .rodata and reconstructing GOT/PLT mappings with LIEF and disassembling main with Capstone, noting its use of memfd_create/fexecve, XOR decoding (0x99), and reported association with UNC5174/VShell intrusion activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.